Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T191E1562481B06BBF612206F09752F712C4EC935FC6ABC9E56A782766B7D8D90D223319 |
|
CONTENT
ssdeep
|
96:TGZzHeuhInM1y411aLTDZspn8Az+nOkmGOcXGoEvsiNxKHHSsxbmkqqysnYm5LM+:akxTyp8AEOkFXGCinKHyshDq5Fo4+ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f6191966764d4d19 |
|
VISUAL
aHash
|
00ffffe7c3e3e7ff |
|
VISUAL
dHash
|
1949704c8c0e4c79 |
|
VISUAL
wHash
|
00cf3f0300000024 |
|
VISUAL
colorHash
|
06400038000 |
|
VISUAL
cropResistant
|
4938580d0c0e4c79,0810300010101000,9bcbcb324ea4a51e |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.